Isolation Forest (Liu, Ting & Zhou, IEEE ICDM 2008) is an unsupervised anomaly detection method. Each isolation tree is built by picking a feature at random, then a random split value between that feature's minimum and maximum — repeatedly, until observations are isolated.
The number of splits needed to isolate an observation equals the path length from the tree's root to its leaf. Averaged over many random trees (an ensemble), a shorter path means the observation is easier to isolate — and more likely to be an anomaly.
The resulting score is a ranking of anomaly signals, not a probability of wrongdoing. Thresholds and interpretation need to be contextualised to each organization's data.
Reference: F. T. Liu, K. M. Ting, Z.-H. Zhou, "Isolation Forest", IEEE ICDM 2008 · scikit-learn documentation: outlier detection.